Main content

CVE-2026-40465
An Open Re-direct Vulnerability in Nokia NSP

Public disclosure

31-08-2026

Last updated

31-08-2026

Vulnerability type

URL Redirection to Untrusted Site ('Open Redirect')

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

CVSS score

5.3

Description

NSP is vulnerable to an open redirect due to insufficient server-side validation of the URL (or redirect) parameter.

Affected products and versions

NSP versions 23.11, 24.4, 24.8, 24.11, 25.4, 25.8 and 25.11.

Mitigation plan

Fixes have been provided in NSP 24.11-SP15, NSP 25.11-SP5, NSP 26.4 and later releases.

Acknowledgements